Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook
Academy home
Helps
Working with Partner management: Data processor, System provider, other stakeholder...

Getting tangled up in terms? We are here to help you!

In this help article, we'll tackle the terminology of partner management, and aid your cybersecurity work with Cyberday.

Ensure compliance with contracts and protection of data used by suppliers.

System providers

Any company that is providing you a data system and/or software is a system provider. System providers are almost always also data processors, and in Cyberday, all system providers are seen as data processors too, so you don't need to do double work. System providers are identified through data systems.

Data processors

Any company that is handling some other data processing activity related to your data stores is a Data processor. These could be for example sales, or billing. Data processors list is in place, to categorize other kind of data processors there, that aren't providing you technical data systems. Data processors are identified through processing purposes for data stores.

Customers

Customer groups whose information you process. Customer groups or individual significant customers that are important to the organization's operations are usually one of the most important stakeholders, also from the point of view of information security.

Other stakeholders

Other companies that are relevant for your cyber security would be other stakeholders. These could be for example facility provider, insurance company or an auditing company.

External data controllers

External data controllers means the owners of the data that you process. They still own and control the data, your organization just process it.

Recipients of data disclosures

Recipients of data disclosures is any party to whom an organisation discloses data, i.e. passes it on without determining how it will be used. For example, some data may be passed on to public authorities in this way.

Additionally, when you work forward from Data systems and Data stores, the companies will "automatically" go to right groups. So a company that gets linked to a data system is put to system providers. Company linked to a data store to data processors.

Questions and feedback

Do you have any further questions, would need another help article or would like to give some feedback? Please contact our team via team@cyberday.ai or the chat box in the right lower corner.

Content

Share article